Return a structured analysis of raw email headers: sender, recipient, subject, date, message id, the Received hop chain with per-hop delays, SPF/DKIM/DMARC results, every public IP seen, and suspicious-routing flags.
This page documents the HTTP endpoint POST /api/tools/email-header-analyzer/execute. See the MCP reference →
Call it over REST
POST https://api.findutils.com/api/tools/email-header-analyzer/execute · no API keys · 60 requests/min per IP
Execute — verified arguments
curl -X POST https://api.findutils.com/api/tools/email-header-analyzer/execute \
-H "Content-Type: application/json" \
-d '{
"headers": "Received: from a.example.com (a.example.com [203.0.113.9]) by mx.example.org; Tue, 18 Aug 2026 10:00:02 +0000\nAuthentication-Results: mx.example.org; spf=pass; dkim=pass; dmarc=pass\nFrom: [email protected]\nTo: [email protected]\nSubject: Hello\nDate: Tue, 18 Aug 2026 10:00:00 +0000\nMessage-ID: <[email protected]>"
}' Parameter schema for this endpoint
curl https://api.findutils.com/api/tools/email-header-analyzer Input schema
| Argument | Type | Required | Description |
|---|---|---|---|
| headers | string | yes | The raw email headers (the "Show original" / "View source" block), including every Received: line. |
Example arguments (verified)
{
"headers": "Received: from a.example.com (a.example.com [203.0.113.9]) by mx.example.org; Tue, 18 Aug 2026 10:00:02 +0000\nAuthentication-Results: mx.example.org; spf=pass; dkim=pass; dmarc=pass\nFrom: [email protected]\nTo: [email protected]\nSubject: Hello\nDate: Tue, 18 Aug 2026 10:00:00 +0000\nMessage-ID: <[email protected]>"
} Also an MCP tool
Claude, Cursor, and any MCP client can call this tool as
findutils:email_header_analyzer after one connect command.
Connect once
claude mcp add findutils --transport http https://mcp.findutils.com/ More Security tools
Base32 Encode
Encode UTF-8 text to RFC 4648 base32 (uppercase, "=" padding).
Data Sanitizer
Sanitize untrusted text and return the cleaned output, a list of changes made, and a risk level.
Dnpm Configurator
Returns the five files of a hardened Docker-based npm wrapper (the ./dnpm bash script, .dnpm/Dockerfile, docker-compose.node.yml, .dnpm/secc
Hash Comparison Tool
Hash text with SHA-1, SHA-256, SHA-384, or SHA-512 and compare the hex digest with an expected hash.
Jwt Decode
Decode a JWT header + payload.
Jwt Generator
Generate a signed JWT (HS256, HS384, or HS512 via HMAC) and return the token plus the decoded header and payload.
Jwt Security Validator
Decode a JWT and return a list of security checks (algorithm strength, expiration, not-before, issued-at, issuer, audience, subject, signatu
Password Breach Checker
Return whether a password appears in known data breaches and how many times, using the Have I Been Pwned k-anonymity range API.